Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2002-08-12 CVE-2002-0498 Privilege Escalation vulnerability in Etnus Totalview 5.0.04
Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.
local
low complexity
etnus
4.6
2002-08-12 CVE-2002-0496 Denial of Service vulnerability in Southwest 1.0.0
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.
network
low complexity
southwest
5.0
2002-08-12 CVE-2002-0492 Remote Security vulnerability in Dcscripts Dcshop 1.002Beta
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
network
low complexity
dcscripts
5.0
2002-08-12 CVE-2002-0487 Unspecified vulnerability in Workforceroi Xpede 4.1/7.0
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g.
local
low complexity
workforceroi
4.6
2002-08-12 CVE-2002-0484 Unspecified vulnerability in PHP
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
network
low complexity
php
5.0
2002-08-12 CVE-2002-0483 Unspecified vulnerability in Francisco Burzi PHP-Nuke
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
network
low complexity
francisco-burzi
5.0
2002-08-12 CVE-2002-0482 Directory Traversal vulnerability in NEWLOG NetSupport Manager 5.5/6.10
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a ..
network
low complexity
newlog
5.0
2002-08-12 CVE-2002-0481 Unspecified vulnerability in Microsoft Outlook 2002
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.
network
high complexity
microsoft
5.1
2002-08-12 CVE-2002-0478 Unspecified vulnerability in Foundrynet Edgeiron 4802F
The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbitrary SNMP community strings.
network
low complexity
foundrynet
5.0
2002-08-12 CVE-2002-0476 Unspecified vulnerability in Macromedia Flash Player 5.0
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.
network
low complexity
macromedia
5.0